<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:56:22 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-326645</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-326645</link>
      <description>EUVD-2026-326645</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-326645</guid>
    </item>
    <item>
      <title>fkie_cve-2026-46673</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46673</link>
      <description>&lt;p&gt;Russh is a Rust SSH client &amp;amp; server library. Prior to version 0.60.3, CryptoVec used unchecked capacity growth, unchecked length arithmetic, and unsafe allocation/locking paths. In current russh releases, local SSH agent peers could still feed attacker-controlled frame lengths into buffer growth before validation. In older russh releases before 0.58.0, remote SSH traffic also reached CryptoVec through transport and compression buffers. This issue has been patched in version 0.60.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Russh is a Rust SSH client &amp;amp; server library. Prior to version 0.60.3, CryptoVec used unchecked capacity growth, unchecked length arithmetic, and unsafe allocation/locking paths. In current russh releases, local SSH agent peers could still feed attacker-controlled frame lengths into buffer growth before validation. In older russh releases before 0.58.0, remote SSH traffic also reached CryptoVec through transport and compression buffers. This issue has been patched in version 0.60.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-46673</guid>
    </item>
    <item>
      <title>GHSA-g9f8-wqj9-fjw5 — Russh: Unchecked CryptoVec allocation and growth handling is reachable</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g9f8-wqj9-fjw5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: russh-cryptovec, crates.io: russh&lt;/p&gt;
&lt;p&gt;### Title
Unchecked `CryptoVec` allocation and growth handling was reachable from local agent inputs in current `russh` releases and from remote SSH traffic in historical pre-`0.58.0` releases&lt;/p&gt;
&lt;p&gt;### Summary
`CryptoVec` used unchecked capacity growth, unchecked length arithmetic, and unsafe allocation/locking paths. In current `russh` releases, local SSH agent peers could still feed attacker-controlled frame lengths into buffer growth before validation. In older `russh` releases before `0.58.0`, remote SSH traffic also reached `CryptoVec` through transport and compression buffers.&lt;/p&gt;
&lt;p&gt;### Details
The underlying unsafe paths were in `CryptoVec`:&lt;/p&gt;
&lt;p&gt;- `cryptovec/src/cryptovec.rs`
  - unchecked capacity growth
  - unchecked length arithmetic in growth callers
  - raw allocation and reallocation paths coupled to those sizes
- `cryptovec/src/platform/unix.rs`
  - `mlock` / `munlock` previously accepted zero-length calls and performed null-pointer validation inside the `unsafe` OS-call path&lt;/p&gt;
&lt;p&gt;There are two relevant reachability stories:&lt;/p&gt;
&lt;p&gt;1. current local reachability in `russh`&lt;/p&gt;
&lt;p&gt;- `russh/src/keys/agent/client.rs`
  - `AgentClient::read_response()` read a peer-supplied `u32` length and then resized `self.buf` to that value before reading the payload
- `russh/src/keys/agent/server.rs`
  - `Connection::run()` read a peer-supplied `u32` length and then resized `self.buf` to that value before reading the payload&lt;/p&gt;
&lt;p&gt;This is the path that still existed in current `0.60.x` releases before the fix,…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: russh-cryptovec, crates.io: russh&lt;/p&gt;
&lt;p&gt;### Title
Unchecked `CryptoVec` allocation and growth handling was reachable from local agent inputs in current `russh` releases and from remote SSH traffic in historical pre-`0.58.0` releases&lt;/p&gt;
&lt;p&gt;### Summary
`CryptoVec` used unchecked capacity growth, unchecked length arithmetic, and unsafe allocation/locking paths. In current `russh` releases, local SSH agent peers could still feed attacker-controlled frame lengths into buffer growth before validation. In older `russh` releases before `0.58.0`, remote SSH traffic also reached `CryptoVec` through transport and compression buffers.&lt;/p&gt;
&lt;p&gt;### Details
The underlying unsafe paths were in `CryptoVec`:&lt;/p&gt;
&lt;p&gt;- `cryptovec/src/cryptovec.rs`
  - unchecked capacity growth
  - unchecked length arithmetic in growth callers
  - raw allocation and reallocation paths coupled to those sizes
- `cryptovec/src/platform/unix.rs`
  - `mlock` / `munlock` previously accepted zero-length calls and performed null-pointer validation inside the `unsafe` OS-call path&lt;/p&gt;
&lt;p&gt;There are two relevant reachability stories:&lt;/p&gt;
&lt;p&gt;1. current local reachability in `russh`&lt;/p&gt;
&lt;p&gt;- `russh/src/keys/agent/client.rs`
  - `AgentClient::read_response()` read a peer-supplied `u32` length and then resized `self.buf` to that value before reading the payload
- `russh/src/keys/agent/server.rs`
  - `Connection::run()` read a peer-supplied `u32` length and then resized `self.buf` to that value before reading the payload&lt;/p&gt;
&lt;p&gt;This is the path that still existed in current `0.60.x` releases before the fix,…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g9f8-wqj9-fjw5</guid>
    </item>
    <item>
      <title>RUSTSEC-2026-0153 — Unchecked `CryptoVec` allocation and growth handling</title>
      <link>https://cve.radiocsirt.org/vuln/rustsec-2026-0153</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: russh-cryptovec&lt;/p&gt;
&lt;p&gt;`CryptoVec` used unchecked capacity growth, unchecked length arithmetic, and
unsafe allocation and locking paths. In affected `russh` releases,
attacker-controlled input could reach these code paths through buffer resizing
operations.&lt;/p&gt;
&lt;p&gt;Two affected reachability paths were identified:&lt;/p&gt;
&lt;p&gt;* **Current `russh` releases (`0.60.x` before the fix)**
  Local SSH agent peers could provide attacker-controlled frame lengths that
  were used to resize internal buffers before validation in:&lt;/p&gt;
&lt;p&gt;* `AgentClient::read_response`
  * `agent::server::Connection::run`&lt;/p&gt;
&lt;p&gt;* **Historical `russh` releases before `0.58.0`**
  `CryptoVec` was also used for non-secret transport and compression buffers,
  allowing remote SSH traffic to trigger `CryptoVec` growth through:&lt;/p&gt;
&lt;p&gt;* transport packet reads
  * zlib decompression output&lt;/p&gt;
&lt;p&gt;These remote paths were removed in `0.58.0` when `CryptoVec` stopped being used
for those buffers.&lt;/p&gt;
&lt;p&gt;Under constrained memory conditions, historical `russh` versions prior to
`0.58.0` can abort the process when remote compressed payload expansion causes
allocation failure in `CryptoVec`. This was reproduced through the compression
path and resulted in process termination in the Unix allocation/locking
implementation after null pointer allocation failure.&lt;/p&gt;
&lt;p&gt;For current affected releases, oversized local SSH agent frame lengths could
trigger untrusted-input-driven buffer growth prior to validation.&lt;/p&gt;
&lt;p&gt;No practical remote code execution, integrity or confidentiality impact has
been demons…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: russh-cryptovec&lt;/p&gt;
&lt;p&gt;`CryptoVec` used unchecked capacity growth, unchecked length arithmetic, and
unsafe allocation and locking paths. In affected `russh` releases,
attacker-controlled input could reach these code paths through buffer resizing
operations.&lt;/p&gt;
&lt;p&gt;Two affected reachability paths were identified:&lt;/p&gt;
&lt;p&gt;* **Current `russh` releases (`0.60.x` before the fix)**
  Local SSH agent peers could provide attacker-controlled frame lengths that
  were used to resize internal buffers before validation in:&lt;/p&gt;
&lt;p&gt;* `AgentClient::read_response`
  * `agent::server::Connection::run`&lt;/p&gt;
&lt;p&gt;* **Historical `russh` releases before `0.58.0`**
  `CryptoVec` was also used for non-secret transport and compression buffers,
  allowing remote SSH traffic to trigger `CryptoVec` growth through:&lt;/p&gt;
&lt;p&gt;* transport packet reads
  * zlib decompression output&lt;/p&gt;
&lt;p&gt;These remote paths were removed in `0.58.0` when `CryptoVec` stopped being used
for those buffers.&lt;/p&gt;
&lt;p&gt;Under constrained memory conditions, historical `russh` versions prior to
`0.58.0` can abort the process when remote compressed payload expansion causes
allocation failure in `CryptoVec`. This was reproduced through the compression
path and resulted in process termination in the Unix allocation/locking
implementation after null pointer allocation failure.&lt;/p&gt;
&lt;p&gt;For current affected releases, oversized local SSH agent frame lengths could
trigger untrusted-input-driven buffer growth prior to validation.&lt;/p&gt;
&lt;p&gt;No practical remote code execution, integrity or confidentiality impact has
been demons…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rustsec-2026-0153</guid>
    </item>
  </channel>
</rss>
